Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2383

Опубликовано: 28 апр. 2014
Источник: debian
EPSS Средний

Описание

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-dompdffixed0.6.1+dfsg-2package

Примечания

  • requires DOMPDF_ENABLE_REMOTE (disabled by default) to be enabled

EPSS

Процентиль: 99%
0.39231
Средний

Связанные уязвимости

ubuntu
больше 12 лет назад

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

nvd
больше 12 лет назад

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

github
больше 4 лет назад

DOMPDF Arbitrary File Read

EPSS

Процентиль: 99%
0.39231
Средний
Уязвимость CVE-2014-2383